Wireless Identity Broker Framework for Mobile Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile communication devices lack the ability to efficiently switch between different wireless communication identities for various user activities and network conditions, limiting their functionality and security in managing multiple roles and environments.
Innovation Solution
The implementation of a wireless communication identity brokering framework that stores multiple wireless communication identities in distinct memory partitions, allowing the device to dynamically switch between them based on location, user selection, or triggering events, using a trusted security zone with hardware-assisted security to manage and protect these identities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple wireless communication identities are stored in the device, then the device can support multiple user roles and network conditions, but the device complexity increases due to memory partitioning and identity management
Solution Approach 1:
The memory is divided into multiple partitions, with each partition storing a specific wireless communication identity. This segmentation allows the device to store multiple identities (e.g., personal, business, roaming) independently, enabling efficient switching between different user roles and network conditions without managing a single large identity database.
Solution Approach 2:
An identity broker application serves as an intermediary between the user/device and the multiple stored identities. This mediator manages the selection, activation, and switching of identities based on triggering events (e.g., location changes, user selection), thereby simplifying the complexity of managing multiple identities by providing a unified control interface.
2Adaptability or versatility
If the device dynamically switches between multiple wireless communication identities, then the functionality for various activities and environments is enhanced, but the ease of operation decreases due to the need to manage and select identities
Solution Approach 1:
The identity broker application automatically performs identity switching based on predefined triggering events such as location changes, time of day, or network conditions. This self-service mechanism reduces the need for manual identity management by the user, thereby enhancing ease of operation while maintaining adaptability to different environments.
Solution Approach 2:
The device pre-configures multiple wireless communication identities in separate memory partitions before they are needed. Each identity is prepared with its own network access parameters and authorization credentials, so when a triggering event occurs, the switch can be executed immediately without requiring real-time configuration or user setup.
3Reliability
If hardware-assisted security is implemented to protect multiple wireless communication identities, then the security and confidentiality are improved, but the device complexity increases due to trusted security zone requirements
Solution Approach 1:
The trusted security zone is divided into multiple partitions, with each partition providing secure storage for a specific wireless communication identity. This segmentation ensures that each identity is protected by its own secure container, preventing unauthorized access or leakage between identities while maintaining hardware-level security.
Solution Approach 2:
The trusted security zone hardware provides a universal security framework that can protect multiple different types of wireless communication identities (e.g., cellular, Wi-Fi, Bluetooth) within a single secure environment. This multi-functional security infrastructure eliminates the need for separate hardware security modules for each identity type, thereby reducing overall device complexity.
Data Source
AI summary
A mobile communication device. The device comprises a cellular radio transceiver, a processor, and a memory integral with the device, wherein the memory is apportioned into a plurality of partitions. The device further comprises a first wireless communication identity stored in a first partition of the memory and a second wireless communication identity stored in a second partition of the memory, wherein the second wireless communication identity is different from the first wireless communication identity. The device further comprises an application stored in the memory that, when executed by the processor, detects a triggering event and in response to the triggering event selects one of the wireless communication identities to be an active communication identity of the device, wherein a wireless communication identity comprises a network access identity and a list of wireless communication systems to which the device is authorized to attach.


